On March 21, 2025, a critical authorization bypass vulnerability in Next.js, identified as CVE-2025-29927, was disclosed with a CVSS score of 9.1. This framework’s middleware handling flaw enables attackers to bypass authentication and authorization, exposing sensitive routes to unauthorized access. Exploiting this vulnerability does not require authentication, providing attackers with direct access to protected routes….
First seen on securityboulevard.com
Jump to article: securityboulevard.com/2025/04/next-js-vulnerability-exposes-middleware-security-gaps/